Trojan

Trojan-Banker.Win32.ClipBanker.k (file analysis)

Malware Removal

The Trojan-Banker.Win32.ClipBanker.k is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.ClipBanker.k virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan-Banker.Win32.ClipBanker.k?


File Info:

crc32: 1F4972A8
md5: 3a859b2e5163540e02f4db4e73fa13bd
name: 3A859B2E5163540E02F4DB4E73FA13BD.mlw
sha1: 67f829cc35cab2f9280e22195a3611303cf614df
sha256: 6a22bdd0577d1d6c7e7a32219dddabd2dd3bd2e36d9587db333c0d371aba1358
sha512: 0ad9d75ca994fb9d4d9df898b4e42e529b280cc218b0d29b59ac1e83a3119e41657f0e5badf2f100b0d5d5cdb728f692d1c48cc5966aad381500c255406861a8
ssdeep: 24576:ODCMA6kxsKEeULRyQ+5CrhSHZnd0iDHs:zzxULRr+5EhSD0iDM
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2001-2012
InternalName: FileZilla Server
FileVersion: 0, 9, 41, 0
CompanyName: FileZilla Project
Comments: Open Source FTP server for Windows
ProductName: FileZilla Server
ProductVersion: 0, 9, 41, 0
FileDescription: FileZilla Server
OriginalFilename: FileZilla server.exe
Translation: 0x0407 0x04b0

Trojan-Banker.Win32.ClipBanker.k also known as:

K7AntiVirusTrojan ( 00531b451 )
CAT-QuickHealTrojan.Sigmal.S2785970
ALYacTrojan.BackSwap.A
CylanceUnsafe
SangforTrojan.Win32.ClipBanker.k
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanBanker:Win32/ClipBanker.8f0bde13
K7GWTrojan ( 00531b451 )
Cybereasonmalicious.e51635
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/BackSwap.A
AvastWin32:Banker-NBP [Trj]
ClamAVWin.Trojan.Backswap-6564636-0
KasperskyTrojan-Banker.Win32.ClipBanker.k
BitDefenderTrojan.GenericKD.30900035
NANO-AntivirusTrojan.Win32.ClipBanker.fdjcoj
ViRobotTrojan.Win32.S.BackSwap.1062400.A
MicroWorld-eScanTrojan.GenericKD.30900035
TencentWin32.Trojan-banker.Clipbanker.Llrh
Ad-AwareTrojan.GenericKD.30900035
ComodoMalware@#2jx8l053z57v8
McAfee-GW-EditionArtemis!Trojan
FireEyeTrojan.GenericKD.30900035
EmsisoftTrojan.GenericKD.30900035 (B)
WebrootW32.Trojan.Gen
AviraTR/AD.Swrort.xdjcc
MicrosoftTrojan:Win32/Bulta!rfn
AegisLabTrojan.Win32.ClipBanker.4!c
GDataTrojan.GenericKD.30900035
TACHYONBanker/W32.ClipBanker.1062400
AhnLab-V3Trojan/Win32.Bulta.C2892793
McAfeeGenericRXAA-AA!3A859B2E5163
MAXmalware (ai score=94)
VBA32Trojan.Bulta
PandaTrj/CI.A
RisingTrojan.BackSwap!8.F9A6 (CLOUD)
YandexTrojan.BackSwap!qwf3xWvwRak
IkarusTrojan-Banker.Backswap
FortinetW32/BackSwap.A!tr
AVGWin32:Banker-NBP [Trj]
Paloaltogeneric.ml

How to remove Trojan-Banker.Win32.ClipBanker.k?

Trojan-Banker.Win32.ClipBanker.k removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment